140 companies, 70 million dollars, and an arrest that undoes none of it
Saif al-Din Khader was picked up in Jordan on Tuesday 29 September. Reuters reported it on Saturday, citing two people familiar with the case, and the detail that matters most is what he is doing now: walking investigators through his own phones and chat logs to help them identify everyone else.
Khader went by Rey. Brian Krebs named him in November 2025 as one of three administrators of Scattered LAPSUS$ Hunters, the loose merger of Scattered Spider, LAPSUS$ and ShinyHunters that has spent two years taking data out of companies and charging them not to publish it. He also ran leak sites for the HellCat ransomware crew and for BreachForums. By the figures cited in the reporting, the group has hit more than 140 organisations since last year and collected at least 70 million dollars in extortion payments: Telefonica's internal ticketing system in January 2025, Orange Romania a month after that, Jaguar Land Rover twice, a long run of firms reached through their Salesforce accounts, and in September an FBI system from which the attackers claimed two to three terabytes of employee, applicant and medical records.
Here is the uncomfortable part. An arrest stops the next breach. It does nothing about the last one. Every name, address, phone number and support ticket this group took has already been copied, sold or filed away in a forum archive, and the people who end up with that material use it for what you would expect: emails that quote your account number, calls that know which bank you use, password resets aimed at an address someone handed over years ago.
So expect the next few months of unusually well-informed messages to be ordinary rather than alarming, and keep the one rule that holds either way: nothing arriving unprompted gets your password, however much it already knows about you. Tendvane's privacy and accounts check will show you which accounts are currently signed in on your PC and what each of them can reach.